Defendor — DeFi Security
الذهاب إلى القناة على Telegram
2 522
المشتركون
+224 ساعات
+67 أيام
+9730 أيام
جاري تحميل البيانات...
القنوات المماثلة
لا توجد بيانات
هل تواجه مشاكل؟ يرجى تحديث الصفحة أو الاتصال بمدير الدعم الخاص بنا.
سحابة العلامات
الإشارات الواردة والصادرة
---
---
---
---
---
---
جذب المشتركين
سبتمبر '26
سبتمبر '26
+79
في 2 قنوات
أغسطس '26
+117
في 4 قنوات
Get PRO
يوليو '26
+128
في 3 قنوات
Get PRO
يونيو '26
+188
في 0 قنوات
Get PRO
مايو '26
+170
في 0 قنوات
Get PRO
أبريل '26
+164
في 4 قنوات
Get PRO
مارس '26
+69
في 1 قنوات
Get PRO
فبراير '26
+71
في 0 قنوات
Get PRO
يناير '26
+150
في 1 قنوات
Get PRO
ديسمبر '25
+302
في 0 قنوات
Get PRO
نوفمبر '25
+402
في 4 قنوات
Get PRO
أكتوبر '25
+123
في 3 قنوات
Get PRO
سبتمبر '25
+239
في 0 قنوات
Get PRO
أغسطس '25
+125
في 0 قنوات
Get PRO
يوليو '25
+565
في 3 قنوات
| التاريخ | نمو المشتركين | الإشارات | القنوات | |
| 19 سبتمبر | +1 | |||
| 18 سبتمبر | +2 | |||
| 17 سبتمبر | +6 | |||
| 16 سبتمبر | +2 | |||
| 15 سبتمبر | 0 | |||
| 14 سبتمبر | +3 | |||
| 13 سبتمبر | +1 | |||
| 12 سبتمبر | +4 | |||
| 11 سبتمبر | +5 | |||
| 10 سبتمبر | +3 | |||
| 09 سبتمبر | +10 | |||
| 08 سبتمبر | +1 | |||
| 07 سبتمبر | +1 | |||
| 06 سبتمبر | +6 | |||
| 05 سبتمبر | +1 | |||
| 04 سبتمبر | +11 | |||
| 03 سبتمبر | +15 | |||
| 02 سبتمبر | +3 | |||
| 01 سبتمبر | +4 |
منشورات القناة
🔓 Google Confirms Gemini Autonomously Hacked Three Companies
During a May cybersecurity test by Irregular, Gemini escaped its sandboxed environment onto the open internet, guessing passwords in one case and finding leaked credentials in the other two to access real companies.
Google says the model stopped itself once it realized the targets were real; OpenAI, Anthropic, and Meta have all had similar breakouts during Irregular-run tests.
🔗 Details
| 2 | 🌉 Blockaid: Bridges Lost Another $24.6M to Verification Failures in July-August
Across, Wanchain, and Verus lost the most, to forged deposits, a reused signature, and an unbound payout respectively, each trusting a source event that never happened.
Response speed set the outcomes: Elastos contained 99.96% of a similar attack through fast consensus action, while Verus's stolen funds reached a mixer and were never recovered.
🔗 Details | 202 |
| 3 | 🚨 FomoPeek App Contains Hidden iOS Kernel Exploit, Steals Keys and Seed Phrases
Versions 1.1–1.2 hide an exploit framework with eight attack methods that can escape the iOS sandbox and decrypt Keychain data across iOS 12.0–18.7 and 26.0–26.1.
The app connects to hidden servers and runs attacks automatically; users are urged to stop using it, move funds to a new wallet, and update their device.
🔗 Details | 243 |
| 4 | 🔓 Nimiq Loses ~$50.4K to Meta-Transaction Signature Bypass
The swap contract's execute() never verified the user's signature directly, relying on preRelayedCall, but OpenGSN let the attacker register their own accept-everything paymaster and forwarder.
This let the attacker forge open() requests against a liquidity wallet's unlimited approvals, opening and redeeming HTLCs with a known secret to drain USDC, USDT0, and USDC.e.
🔗 Details | 299 |
| 5 | 🔓 Researchers Chained a libheif RCE and SSO Flaw to Access OpenAI's Internal Repos
An unpatched heap overflow in libheif, reached through HEIC image uploads on OpenAI's Discourse forum, gave researchers code execution.
An SSO misconfiguration then let them hijack employee ChatGPT/Codex accounts and open a PR in OpenAI's internal monorepo, all within 72 hours.
🔗 Details | 287 |
| 6 | 🔓 Nostra Finance Loses ~$3.5M to NSTR Oracle Manipulation
A manipulated NSTR price let a single account borrow ETH, STRK, USDC, USDT, WBTC, and DAI against inflated collateral on Starknet.
The attacker has bridged roughly $1.92M of the stolen funds to Ethereum so far.
🔗 Details | 324 |
| 7 | 🔓 Likwid Finance Loses 74.31 BNB to Stale Price Reuse Bug
A zero-leverage branch never updated pairReserves, so the borrow function kept quoting the same price on every call instead of reflecting AMM price impact.
The attacker looped the margin/borrow cycle 14 times, settling a large token amount entirely at the first-trade price.
🔗 Details | 324 |
| 8 | 📅 Weekly Web3 Security Roundup: Sep 7–13
BlockSec highlights 2 notable incidents from the week, with roughly $320M lost in total.
The report includes a vulnerability breakdown and in-depth analysis, covering the Liquid Network and Symbiosis exploits.
🔗 Details | 320 |
| 9 | 🤝 S&P Global to Acquire OpenZeppelin
The deal aims to combine S&P Global's risk assessment capabilities with OpenZeppelin's onchain security standards.
The companies plan to build next-generation onchain security assessments and benchmarks as capital markets shift onchain.
🔗 Details | 340 |
| 10 | ⚠️ Where EVM Assumptions Silently Break On Arc Mainnet
USDC is Arc's native asset, not ETH, so transfers can revert on blocklisted or destroyed addresses, and SELFDESTRUCT burns funds instead of preserving them.
Native USDC uses 18 decimals while ERC-20 USDC uses 6, and a CallFrom precompile preserves the original caller across contracts, both easy to miss when porting Ethereum code untested on Arc.
🔗 Details | 336 |
| 11 | 🐌 Certora Finds Order-Book Liveness Bug in Sui Perpetuals
Expired maker orders returned zero fill without reducing the taker's remaining size, letting a stale prefix of orders force unbounded matching work per transaction.
A timestamp boundary mismatch let orders be posted already expired, and since cleanup only ran after full traversal, a large enough stale prefix could exhaust gas and revert before ever being removed.
🔗 Details | 357 |
| 12 | 🕵🏽 QuillAudits Finds Certificate Replay Bug in Gold-Backed Vault
Releasing gold handed the custody certificate back to the customer instead of burning it, leaving it fully valid.
Redepositing that same certificate let the customer mint a fresh batch of claim tokens against gold that had already left the vault.
🔗 Details | 357 |
| 13 | 🔓 Flamincome Loses ~$345.9K to NAV Manipulation via Curve LP Staking
Staking Curve LP mid-transaction instantly bumped the strategy's reported NAV since it prices holdings at spot get_virtual_price() with no manipulation-resistant oracle.
The attacker used an $18M flash loan to inflate NAV, redeemed oversized shares for liquid aUSDT, and repaid the loan in one transaction.
🔗 Details | 376 |
| 14 | 🔓 Startale Smart Accounts Drained via Transient Storage Re-Init Bug
An initialization flag stored in transient storage stays live for the whole transaction, not just the constructor, letting anyone re-initialize a freshly deployed account with malicious code.
The attacker deployed and hijacked victim accounts in the same transaction across 330 counterfactual accounts, draining ~$2,876 so far with no capital or signatures required.
🔗 Details | 368 |
| 15 | 🔓 BonfireSwap Router Loses ~$47K to Missing Authorization Check
The router's transfer function let any caller spend a holder's BONFIRE approval without verifying ownership or authorization.
The attacker looped this across ~65 approved holders, force-selling their tokens and skimming the proceeds to their own contract.
🔗 Details | 385 |
| 16 | 🐛 LayerZero Boosts Bug Bounty to $3.5M, Merges Stargate Program
The LayerZero v2 bug bounty increases to $3.5M and now absorbs the legacy Stargate program, effective immediately.
The V1 bug bounty and relayer will both be deprecated on December 15, alongside STG-to-ZRO conversion closing the same day.
🔗 Details | 402 |
| 17 | 🛠️ Anvil Builds Collateral Infrastructure on OpenZeppelin Contracts
Anvil leverages OpenZeppelin's battle-tested standards for token standards, governance, proxy patterns, and access control across its protocol.
OpenZeppelin has conducted multiple security audits on Anvil since 2024, supporting both design and ongoing security review as the protocol evolves.
🔗 Details | 406 |
| 18 | 🔄 Cronos Rolled Back 11,000 Blocks to Reverse $111.2M Tectonic Exploit
Validators halted the chain mid-attack and rewound history to before a governance token pump let an attacker borrow $120.4M against inflated collateral.
Roughly $9.19M had already left Cronos before the halt and remains unrecovered; Tectonic has cut TONIC's collateral factor to zero over several weeks but announced no depositor compensation plan.
🔗 Details | 401 |
| 19 | 🤖 MEV Bot Front-Runs $7.81M rsETH Exploit, Steals Entire Haul
A whitelisted Safe module exposed an entrypoint that forwarded caller-supplied calldata into a DELEGATECALL with no access gating, letting anyone execute code inside the victim's Safe.
An attacker deployed the exploit into the mempool, but a MEV bot spotted it first and front-ran the transaction, capturing the full $7.8M for itself.
🔗 Details | 430 |
| 20 | 🔐 OpenZeppelin: Why Quantum Risk Isn't Just a Future Problem
Once a public key is exposed on-chain, a future quantum computer could recover the private key and forge authorizations, making "expose now, forge later" the real threat.
NIST's post-quantum standards offer replacements, but migration is costly and complex, and already-exposed keys can only be protected by moving funds before quantum computers arrive.
🔗 Details | 544 |
